Vulnerabilities & Exploits

Mail Gateway Flaws Expose Traffic and Internal Access

SEPPMail is more than a filtering layer here. A compromise can expose protected mail flows and give an attacker a foothold inside the network, so patching this box is not just about closing a web flaw.

InfoGuard Labs disclosed seven SEPPMail Secure E-Mail Gateway vulnerabilities at once, covering remote code execution, path traversal, authorization bypass, deserialization, and eval injection. The issues affect the Secure E-Mail Gateway appliance and are fixed across staggered releases from 15.0.2.1 through 15.0.4.

The practical problem is blast radius. A vulnerable gateway can reveal arbitrary mailbox traffic and act as an entry point into the internal network, so some appliances remain exposed until the right 15.0.x fix is in place.

1 source · May 19

CVEs in this update

7 CVEs

1 critical · 0 high · 0 medium · 0 low

0 in CISA KEV · 2 with EPSS above 1%

Highest severity: CVE-2026-2743 · 9.8 CRITICAL

Highest EPSS: CVE-2026-7864 · 17%

Timeline

Sources

Part of the PlainSec briefing for 2026-05-20

Every edition of this story: Mail Gateway Flaws Expose Traffic and Internal Access

More from today